Latest / Tech Talks With Kinsoft / Diagnosis Compromised: The Human Cost of Medical Data Leaks and the Privacy Fix
Transcript
- 0:00Hello and welcome back to Tech Talks with Kinsoft.
- 0:02Great to be here. It is Friday, January 16th,
- 0:042026. And, you know, there's usually that specific
- 0:09energy in the air this time of year. Right. The
- 0:11new year, new me feeling. Exactly. Everyone's
- 0:14back at their desks. The resolutions are still
- 0:16technically alive and we're all hoping for a
- 0:17fresh start. But looking at the stack of reports
- 0:20on the desk today, it seems the digital landscape
- 0:23didn't get the memo. No, it definitely did not.
- 0:27If anything, the holiday break just gave the
- 0:29threat actors time to reload. We're barely two
- 0:32weeks into 2026, and the sheer volume of data
- 0:35breaches hitting Australian infrastructure is
- 0:37frankly relentless. That's what I was thinking.
- 0:39And what's striking is that it isn't just the
- 0:41usual suspects. We're not just talking about
- 0:43big tech firms or banks. That is what jumped
- 0:45out at me going through this pile. Yeah. It feels
- 0:47like a scattergun approach. We're seeing, what,
- 0:49gold mines, primary schools, ear, nose, and throat
- 0:52specialists. It feels like no one is off limits.
- 0:56It looks like chaos, but when you zoom in, there
- 0:59is a logic to it. We have a lot to get through
- 1:02today. We really need to unpack this January
- 1:04onslaught to understand the immediate risks.
- 1:08Okay. But I also want to take us into the weeds
- 1:10on why the healthcare sector specifically is
- 1:14becoming such a massive target right now. And
- 1:17later, we have to talk about the future. You
- 1:19mean the sci -fi stuff we were talking about
- 1:20before? The sci -fi stuff that is becoming reality.
- 1:23Yeah, faster than we'd like. We're talking about...
- 1:25harvest now, decrypt later strategies involving
- 1:28quantum computing. Right. And the countermeasures,
- 1:30really heavy but fascinating math like homomorphic
- 1:34encryption, that might be the only way to save
- 1:37our privacy in the long run. Sounds intense but
- 1:39necessary. OK, let's start with the ground reality.
- 1:42We're looking at December 2025 into these first
- 1:45two weeks of January 2026. The reports call this
- 1:48a surge. Is that statistical or are we just paying
- 1:51more attention? Oh, it's absolutely statistical.
- 1:53The volume is staggering and the impact is hitting
- 1:56the most vulnerable demographics. I mean, look
- 1:58at the Victorian Department of Education breach
- 2:00that broke just this month. That was the one
- 2:02affecting all 1 ,700 government schools, right?
- 2:05Every single one. Yeah. Wow. And the detail here
- 2:08is, I mean, it's vital. It wasn't just. Current
- 2:10students, it was former students, too. Oh, that's
- 2:12bad. When you breach an education department,
- 2:15you're not just stealing a database of names.
- 2:17You're mapping out families. You have names,
- 2:20addresses, potentially behavioral records, special
- 2:24consideration notes. That is data that can be
- 2:27weaponized for identity theft against minors
- 2:30who might not realize their identity has been
- 2:32compromised for years. For years, exactly. It's
- 2:35a nightmare for parents. It's not like a credit
- 2:37card where you get a notification. It's silent.
- 2:39And then you pivot from the public sector to
- 2:41something like... Prezura, their car rental insurer,
- 2:45they got hit in January too. 300 ,000 customers
- 2:48exposed there. Right. And this illustrates the
- 2:50whole supply chain risk. Right. You might not
- 2:53think your car rental insurance is high risk
- 2:54data. It feels, you know, transactional, but
- 2:57it connects to your driver's license, your credit
- 2:59card, your travel habits, your home address.
- 3:02It's a full kit for a fraudster. And then we
- 3:05have the corporate heavy hitters, Regis Resources,
- 3:08an ASX listed gold producer. I have to admit,
- 3:12when I saw a gold mine hacked, my brain went
- 3:15to some movie scene. Right, where someone is
- 3:17digitally stealing gold bars. Yeah, which I know
- 3:20isn't how it works. Not quite the Italian job,
- 3:22no. But in a way, it's more damaging. When a
- 3:25resource giant like Regis gets breached, it rattles
- 3:29the market. It exposes supply chain contracts,
- 3:32geological data, employee records. It shows that
- 3:35physical security guards, fences. Doesn't translate.
- 3:38It doesn't translate to digital security. They're
- 3:40digital. walls came down in January. And we can't
- 3:43forget the University of Sydney breach from back
- 3:45in December that affected 27 ,000 people, staff,
- 3:49alumni, donors. It just feels like a free for
- 3:52all. Who is actually pulling the strings here?
- 3:54Well, we need to stop thinking of them as hackers
- 3:55in hoodies and start thinking of them as enterprises.
- 3:58As businesses. They are businesses. We're seeing
- 4:01attribution to specific ransomware groups like
- 4:03SafePay. They claimed the attacks on Beatsy Acres
- 4:06Jewelers and Snowbrand Australia recently. Then
- 4:09you have groups like INC Ransom and Quinlan.
- 4:12They have brands. That is wild. They have brands.
- 4:16They have HR departments. They have press releases.
- 4:18Yeah. And they have customer service desks to
- 4:21help you pay the ransom. It's... Ransomware as
- 4:23a service. Unbelievable. And they are operating
- 4:25aggressively in the Australian theater right
- 4:27now because they know the targets are rich. And
- 4:30frankly, the defenses are often lagging. That
- 4:34brings me to a statistic in the CISA report that
- 4:36I found incredibly frustrating. We talk about
- 4:39these sophisticated syndicates, you know, Quillen
- 4:42and SafePay. And I'm picturing laser grids and
- 4:45Mission Impossible stunts. Right. But the report
- 4:48says 90 percent of successful attacks still start
- 4:51with email. 90%. It is the most depressing statistic
- 4:55in cybersecurity. It has to be. You can spend
- 4:57millions on firewalls, intrusion detection, AI
- 5:00monitoring. But if someone in accounts payable
- 5:02receives an email that looks like an overdue
- 5:04invoice and they click that link, the millions
- 5:06of dollars of defense are just bypassed. So the
- 5:08human is the firewall and the human is tired,
- 5:11stressed and clicking things. Exactly. Social
- 5:14engineering exploits the human operating system,
- 5:17which hasn't been patched in about 200 ,000 years.
- 5:20We're curious, we're helpful, and we're fearful
- 5:22of authority. Phishing exploits all three. Well,
- 5:25that human vulnerability seems to be hitting
- 5:27one sector harder than any other right now. I
- 5:30want to shift focus to health care. Looking at
- 5:33the list, Point, Lonsdale Medical, Genie IVF,
- 5:37the ENT Center, it feels targeted. It is targeted,
- 5:40absolutely. Health care is the perfect storm
- 5:42for cybercrime. First, you have the value of
- 5:44the data. If your credit card is stolen, what
- 5:46do you do? I call the bank, cancel it, get a
- 5:48new one on Tuesday. It's annoying, but that's
- 5:51it. Right. It's an inconvenience. Now, what if
- 5:53your mental health records are stolen? What if
- 5:55your genetic profile is stolen or your history
- 5:57of addiction treatment? You can't cancel that.
- 5:59You cannot cancel your DNA. You can't change
- 6:01your medical history. That data is permanently
- 6:04valuable for blackmail, for synthetic identity
- 6:07theft, even for insurance fraud. The permanence
- 6:10is what makes it terrifying. The Genie IVF breach
- 6:12back in February 2025. That one really stuck
- 6:16with me. It should. The claim was somewhere between
- 6:19700 to 940 gigabytes of data. A terabyte. Nearly
- 6:23a terabyte. It's immense. And think about the
- 6:26nature of that data. Fertility treatment is incredibly
- 6:28intimate, emotional, financial. Exposing that
- 6:32is devastating. Of course. And the attackers
- 6:34know that hospitals and clinics are more likely
- 6:36to pay ransoms because lives and privacy are
- 6:38strictly on the line. But why are they so easy
- 6:41to get into? Is it just the phishing? Phishing
- 6:44is the entry, but the environment is the problem.
- 6:46We call it the systemic weakness of health care.
- 6:50You have this concept of medjack. Medical device
- 6:52hijacking. Exactly. Walk into a hospital room,
- 6:55you see MRIs, infusion pumps, patient monitors.
- 6:59Many of these are networked. So the MRI machine
- 7:01is on the Wi -Fi. Often, yes, to send images
- 7:04to the radiologist or patient data to the central
- 7:06server. But here's the kicker. That MRI machine
- 7:09might be running on Windows 7. Or even older.
- 7:11Or even Windows XP embedded. And it can't be
- 7:14patched. Why not? Just run an update. You often
- 7:16can't. If you update the operating system, you
- 7:19might void the FDA or TGA approval for that medical
- 7:22device. Or the vendor no longer supports it.
- 7:25So you have these multi -million dollar machines
- 7:27that are essentially open windows into the network.
- 7:30That reminds me of the Wannacray attack a few
- 7:32years back. The UK's National Health Service
- 7:34got absolutely leveled by that, didn't it? That
- 7:36is the classic case study. WannaCry wasn't even
- 7:40targeting hospitals specifically. It was a worm
- 7:43that just spread. But it crippled the NHS because
- 7:45they were reliant on obsolete Windows XP systems.
- 7:48Wow. Ambulances were diverted. Surgeries canceled.
- 7:51It proved that cybersecurity isn't an IT issue.
- 7:55It's a patient safety issue. There's a saying
- 7:57you mentioned in the notes about this sector.
- 7:59It was pretty cynical. There are only two types
- 8:01of health care organizations, those that know
- 8:03they've been hacked and those that don't. That
- 8:05is comforting. Not. It's the reality. And it's
- 8:08compounded by retention. In healthcare, you are
- 8:11legally required to keep patient records for
- 8:13decades, often 30 years or more. Right. So you're
- 8:16sitting on a dragon's hoard of data, protecting
- 8:19it with aging infrastructure, and humans who
- 8:22are stressed and clicking emails. Okay, so that
- 8:25is the here and now. We have sensitive data sitting
- 8:28on old computers. But the research you brought
- 8:30today points to something that honestly scared
- 8:32me more than the current breaches. This concept
- 8:36of harvest now, decrypt later. This is where
- 8:39we get into the strategic long -term threat.
- 8:42This is what intelligence agencies and advanced
- 8:45criminal groups are doing right now. Walk me
- 8:47through this, because usually if I encrypt my
- 8:49data, I feel safe. I see a little padlock icon
- 8:52I know my database is encrypted with. AES -256
- 8:56or whatever. Yeah. I assume if a hacker steals
- 8:58it, they just get gibberish. And for today, you're
- 9:00right. If they steal your encrypted database,
- 9:02it looks like random noise. They can't read it,
- 9:04but storage is cheap. So they keep it. They keep
- 9:07it. They harvest it. Waiting for what? A password
- 9:10leak? They're waiting for the math to break.
- 9:12Specifically, they're waiting for quantum computing.
- 9:14See, our current encryption RSA, which secures
- 9:18almost everything on the internet. It relies
- 9:20on a specific math problem. Factoring large numbers.
- 9:23Factoring very large numbers. It's incredibly
- 9:26hard for a classic computer to do. It would take
- 9:28millions of years. But a quantum computer changes
- 9:31the math. Fundamentally. There's a concept called
- 9:34Shor's algorithm. Without getting too bogged
- 9:36down in the physics, it's a quantum algorithm
- 9:38that can factor those large numbers terrifyingly
- 9:42fast. Once a quantum computer is powerful enough
- 9:45to run Shor's algorithm at scale, it acts like
- 9:48a skeleton key. So that encrypted file from 2026.
- 9:51Suddenly unlocks. It becomes plain text. So if
- 9:53I'm a hospital and I'm required to keep records
- 9:56for 30 years, data I save today might be safe
- 10:00for 5 or 10 years. But in year 11, the quantum
- 10:03computer comes online and suddenly all those
- 10:05secrets are out. Precisely. That is the decrypt
- 10:08later part. If you have data that needs to remain
- 10:10secret for 15, 20, 50 years. national secrets,
- 10:14genetic data, mental health records, you are
- 10:16already in the danger zone. We are racing against
- 10:19a clock we can't see. That makes data retention
- 10:21feel like a ticking time bomb. But you also mentioned
- 10:24another futuristic threat that's actually happening
- 10:26now involving AI. Shadow data. I've heard of
- 10:31shadow IT. Is this related? It's different and
- 10:33in some ways more insidious. This relates to
- 10:36how we use large language models or LLMs in business.
- 10:39Imagine a hospital trains a private AI on its
- 10:42internal records to help doctors write summaries.
- 10:45Which sounds like a great productivity tool.
- 10:47It is. But that AI model has now learned the
- 10:51patterns of that private data. Attackers are
- 10:53finding ways to use what we call constructive
- 10:55prompt injection. Is that like jailbreaking the
- 10:58AI? Sort of. They don't need to hack the database.
- 11:01They just talk to the AI. By asking a series
- 11:04of specifically designed questions, they can
- 11:06trick the model into regurgitating or reconstructing
- 11:09the training data. So they ask, tell me about
- 11:12the patient with a rare heart condition in room
- 11:14302. Or even more subtle queries that leverage
- 11:16the AI's pattern matching, like complete this
- 11:19sentence based on the clinical notes regarding
- 11:21patient X. The AI, trying to be helpful, fills
- 11:25in the blanks with the real confidential data
- 11:27it was trained on. So it leaks the secrets. It
- 11:29effectively leaks them. That reconstructed information
- 11:32is shadow data. That is wild. It's like the data
- 11:35is a ghost haunting machine. You can't find the
- 11:39file. But the machine knows the secret. And it's
- 11:41very hard to defend against because the AI is
- 11:44doing exactly what it was designed to do, predict
- 11:47the next word. Okay, I need a lifeline here.
- 11:49We've got quantum computers smashing our locks,
- 11:52AI chatting away our secrets. Please tell me
- 11:55the research included some solutions. Or should
- 11:58we just go back to pen and paper? Pen and paper
- 12:00has its own risks. No, there is hope. And ironically,
- 12:02the solution to the math problem is more math.
- 12:05Better math. Better math. There are two concepts
- 12:08that are critical for the next decade of privacy,
- 12:10differential privacy and homomorphic encryption.
- 12:13Let's break them down. Differential privacy,
- 12:15or DP, is this about hiding data? It's about
- 12:19hiding the individual within the data. Think
- 12:21about medical research. We want to know trends.
- 12:24Does this drug work for people over 50? To answer
- 12:27that, we need patient data. But if you query
- 12:30a database enough times with specific questions,
- 12:32you can triangulate a specific person. How many
- 12:35people over 50 live on Smith Street and have
- 12:37diabetes? Suddenly you know it's Bob. Exactly.
- 12:41Differential privacy fixes this by injecting
- 12:44calibrated noise into the results. It's like
- 12:47looking at a photo through frosted glass. You
- 12:49can clearly see the shape of the tree, but you
- 12:51can't count the individual leaves. So the researcher
- 12:54gets the trend they need. But BOP remains invisible.
- 12:58Correct. It provides a mathematical guarantee
- 13:00that the output is statistically accurate for
- 13:03the group, but implies nothing about any single
- 13:06individual. It protects the entropy of the data.
- 13:09Okay, that handles research. But what about processing?
- 13:12You mentioned homomorphic encryption as the holy
- 13:14grail. That's a big title. It earns it. The biggest
- 13:17weakness in security right now is that to do
- 13:19anything with data, analyze it, search it, you
- 13:22have to decrypt it first. You have to unlock
- 13:25the box. And the moment the box is open, the
- 13:27data is vulnerable. To the hacker, the malware,
- 13:30the rogue employee, everything. So homomorphic
- 13:33encryption keeps the box locked. It allows you
- 13:36to work inside the locked box. Imagine you have
- 13:38a sensitive gold artifact in a locked steel safe.
- 13:41You want a specialist to clean it and weigh it.
- 13:44In the old world, you give them the key. Trusting
- 13:47them entirely. With homomorphic encryption, you
- 13:49give them the safe, but you've built special
- 13:51gloves into the side of the safe. They can reach
- 13:54in, manipulate the object, clean it, weigh it,
- 13:58but they can never see it directly or take it
- 14:00out. That's a fantastic analogy. Yeah. So a hospital
- 14:04could send encrypted data to the cloud. And the
- 14:06cloud server runs the algorithms, does the number
- 14:09crunching on the gibberish ciphertext, and sends
- 14:12the result back. The cloud provider never sees
- 14:14the patient's name, never sees the diagnosis.
- 14:16The data never exists as plain text outside the
- 14:20hospital's control. That seems like it solves
- 14:22everything. Why isn't everyone doing this today?
- 14:24It's incredibly computationally expensive. Working
- 14:26through the gloves is slow. It takes a lot of
- 14:28processing power. But for high value data like
- 14:31health care or finance, the tradeoff is becoming
- 14:34worth it. So the math is the future. But we have
- 14:37to survive the present. We established earlier
- 14:39that Dave in accounting is still clicking phishing
- 14:42links. We can't wait for quantum proof clubs
- 14:44to stop that. No. For the human error problem,
- 14:48we need a different approach. The buzzword you'll
- 14:50hear is zero trust, but it's more than a buzzword.
- 14:53It's a philosophy. Trust no one. Sounds paranoid.
- 14:56It's professionally paranoid. The old model was
- 14:59castle and moat. You have a firewall, the moat.
- 15:02Once you cross the drawbridge and log in, you're
- 15:05inside the castle. You can roam the halls. And
- 15:08if a hacker steals my badge, they can roam the
- 15:10halls too. Exactly. Zero Trust says, I don't
- 15:12care if you're in the castle. Every single room
- 15:14is locked. Every time you want to access a file
- 15:16or a server, you have to prove who you are again.
- 15:20Continuous authentication. The notes mentioned
- 15:22a specific way to do this, technically a jump
- 15:26host. Yeah. This is a very practical, immediate
- 15:29step organizations can take. Instead of connecting
- 15:32your sensitive database directly to your corporate
- 15:34network, you put it behind a jump host. Think
- 15:37of it like an airlock on a submarine. Okay, I
- 15:39like that image. You connect to the jump host
- 15:42via a secure VPN. You verify yourself there.
- 15:45Then, and only then, does the jump host open
- 15:48a connection to the database. It breaks the line
- 15:50of sight. So a hacker on my laptop can't see
- 15:52the database. They can't just ping the database
- 15:54and they hit a wall. The report specifically
- 15:57suggests using stable, secure systems like Ubuntu
- 16:00with OpenVPN for this. It's not expensive. It's
- 16:03just good architecture. And I assume, even with
- 16:06airlocks and fancy math, we still need to tell
- 16:08Dave not to click the link. You can never stop
- 16:11training. Technology fails without people. The
- 16:14reports emphasize that security awareness training
- 16:17can't be a once a year boring video. It has to
- 16:20be constant. You have to build a culture where
- 16:22people are suspicious of email. Right. Because
- 16:25if you can reduce that 90 percent failure rate,
- 16:27the rest of your security stack actually has
- 16:29a chance to work. It really is a full spectrum
- 16:31battle. We started with the chaos of January
- 16:332026 schools and insurers getting hit. We looked
- 16:36at the specific vulnerability of health care.
- 16:38We scared ourselves with quantum decryption and
- 16:40then, you know, found some hope in homomorphic
- 16:43encryption and zero trust. It's an arms race.
- 16:45It always has been. But we are getting better
- 16:48tools. Before we wrap up, I want to circle back
- 16:50to one thing you said about harvest now, decrypt
- 16:53later. Yeah. It led to a pretty provocative thought
- 16:56in our prep session regarding. Well, data hoarding.
- 16:59Yes. This is the question I want every listener
- 17:02to ask themselves today. We have been taught
- 17:05that data is the new oil, that we should save
- 17:08everything because it might be valuable later.
- 17:10Right. Data is an asset. But in a world where
- 17:12quantum computing breaks encryption, that stockpile
- 17:17of data isn't an asset. It's a liability. The
- 17:19toxic asset. Exactly. If you don't need the data,
- 17:22delete it. Data minimization is the only security
- 17:26measure that is 100 % effective. You cannot hack
- 17:29what does not exist. That is a powerful takeaway.
- 17:31Maybe the best firewall is the delete key. It
- 17:34usually is. Well, if this conversation has made
- 17:36you realize that maybe your organization's digital
- 17:38walls are a bit thinner than you'd like, or if
- 17:41you're wondering if your jump host is actually
- 17:43set up correctly, you can't do this alone. No,
- 17:45you need expertise. You need partners who live
- 17:48and breathe this stuff. If you want to discuss
- 17:50your security architecture and IT needs, you
- 17:52need to head over to www .kinsoft .com .au. That's
- 17:57K -I -N -S -O -F -T dot com forward dot A -U.
- 18:01Whether it's setting up Zero Trust or just figuring
- 18:03out where your data actually lives, they can
- 18:05help you navigate the minefield. Don't wait until
- 18:07you're the headline. Thanks for joining us on
- 18:09Tech Talks with Kinsoft. Stay safe, stay skeptical,
- 18:12and we'll catch you next time.